2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3546 | HIGH | 8.2 | 0.5% | Jun 2, 2021 | An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions ... |
| CVE-2021-24012 | HIGH | 7.3 | 0.5% | Jun 2, 2021 | An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an ... |
| CVE-2021-23895 | HIGH | 8 | 1.9% | Jun 2, 2021 | Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authe... |
| CVE-2021-23894 | HIGH | 8.8 | 2.2% | Jun 2, 2021 | Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unaut... |
| CVE-2021-29090 | HIGH | 7.2 | 1.7% | Jun 2, 2021 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in S... |
| CVE-2021-32656 | HIGH | 8.6 | 1.8% | Jun 1, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions... |
| CVE-2021-31684 | HIGH | 7.5 | 2.3% | Jun 1, 2021 | A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which c... |
| CVE-2021-22123 | HIGH | 8.8 | 77.3% | Jun 1, 2021 | An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x,... |
| CVE-2021-32924 | HIGH | 8.8 | 19.9% | Jun 1, 2021 | Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because th... |
| CVE-2021-3516 | HIGH | 7.8 | 2.0% | Jun 1, 2021 | There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be pr... |
| CVE-2021-3495 | HIGH | 8.8 | 1.0% | Jun 1, 2021 | An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw ... |
| CVE-2021-3412 | HIGH | 7.3 | 0.8% | Jun 1, 2021 | It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap... |
| CVE-2021-33184 | HIGH | 7.7 | 1.0% | Jun 1, 2021 | Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15... |
| CVE-2021-33183 | HIGH | 7.9 | 0.3% | Jun 1, 2021 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management... |
| CVE-2021-32027 | HIGH | 8.8 | 2.0% | Jun 1, 2021 | A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While... |
| CVE-2021-29740 | HIGH | 7.8 | 0.3% | Jun 1, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string ... |
| CVE-2021-29665 | HIGH | 7.8 | 1.1% | Jun 1, 2021 | IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking whic... |
| CVE-2021-29092 | HIGH | 8.8 | 1.7% | Jun 1, 2021 | Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station bef... |
| CVE-2021-29088 | HIGH | 7.8 | 0.3% | Jun 1, 2021 | Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation ... |
| CVE-2021-24312 | HIGH | 7.2 | 1.7% | Jun 1, 2021 | The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_p... |
| CVE-2021-24311 | HIGH | 8.8 | 1.8% | Jun 1, 2021 | The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitr... |
| CVE-2021-20576 | HIGH | 7.5 | 2.5% | Jun 1, 2021 | IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could c... |
| CVE-2021-23019 | HIGH | 7.8 | 0.2% | Jun 1, 2021 | The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt fil... |
| CVE-2021-23017 | HIGH | 7.7 | 52.8% | Jun 1, 2021 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t... |
| CVE-2021-23018 | HIGH | 7.4 | 0.5% | Jun 1, 2021 | Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are us... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now